GDPR · EU and UK

GDPR data protection
awareness for your people.

GDPR requires appropriate technical and organisational security for personal data, including a process for regularly testing and evaluating how well those measures work, and gives the data protection officer the task of awareness-raising and training for staff involved in processing.

Framework
GDPR, Regulation (EU) 2016/679, and UK GDPR
Security
Article 32, including regular testing of effectiveness
Staff
Article 39(1)(b): awareness-raising and training of staff
Breaches
Notify the supervisory authority within 72 hours (Article 33)

What GDPR says about people

Security has to be tested,
not just written down.

The articles below are in force.

ProvisionWhat it saysStatus
Article 32(1)Appropriate technical and organisational measures ensure a level of security appropriate to the risk.In force
Article 32(1)(d)A process for regularly testing, assessing and evaluating the effectiveness of those measures.In force
Article 39(1)(b)The data protection officer’s tasks include awareness-raising and training of staff involved in processing.In force
Article 33(1)Notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.In force
UK Data (Use and Access) Act 2025Most of the UK’s data protection changes commenced on 5 February 2026.In force in the UK

Breaches start with people

One click can
expose a customer list.

A credential entered on a fake login page, or a file sent to the wrong person, can become a personal data breach.

SAMPLE PROGRAMME

Data protection awareness

  • Data protection policy acknowledged
  • Micro-lesson: handling personal data safely
  • Credential-capture simulation
  • Phishing Reporter in every mailbox
  • Evidence review with the DPO

Illustrative programme.

Expectation to record

Awareness you can
show your DPO.

TRAINING

Staff trained on data protection.

LMS completions, assessments and certificates.

POLICY ACKNOWLEDGEMENTS

Staff accept your data policies.

Dated records per person and version.

SIMULATION RESULTS

Staff tested against phishing.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

Policy Manager records employee policy acknowledgement. It is not a consent-management system for customer or data-subject consent. KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. Regulation (EU) 2016/679 (GDPR)Articles 32, 33 and 39
  2. Data (Use and Access) Act 2025Royal Assent 19 June 2025 · most provisions from 5 February 2026
  3. ICO statement on commencement of the Data (Use and Access) ActFebruary 2026

Questions buyers ask

Frequently asked questions.

Is the 72-hour breach deadline changing?

Not yet. The European Commission’s Digital Omnibus proposal would change breach reporting, but it is still being negotiated. Today the deadline under Article 33 is 72 hours.

What changed in the UK?

The Data (Use and Access) Act 2025 amended UK data protection law, with most changes in force from 5 February 2026. The security duty and 72-hour breach reporting remain.

Does KeenSec make us compliant with GDPR?

No tool makes you compliant on its own. KeenSec helps you evidence employee data protection awareness; your DPO, counsel and supervisory authority decide compliance.

Is Policy Manager a consent-management tool?

No. It records employee acknowledgement of internal policies. Customer or data-subject consent needs a separate consent process.

Let’s connect the dots

Protect the data
by preparing the people.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo